Method of Infection

This file tries to spread via email and by copying itself to the shared directory for Kazaa clients if they are present.

The mailing component harvests address from the local system. Files with the following extensions are targeted:

wab
adb
tbb
dbx
asp
php
sht
htm
txt
Additionally, the worm contains strings, which it uses to randomly generate, or guess, addresses.

10,198 views 9 replies
Reply #1 Top
that was close!! i was just about to check my email but decided i would checke wincustomize first and, i saw your news post and updated my norton right away then when i whent to check my email i found 5 emails with the vrius!!!lol

thanks for the post yrag
Reply #2 Top
thanks for the info
Reply #3 Top
Glad my definitions are up to date
Reply #4 Top
Yesterday NAI mailed about an emergency update (4318 files) and 9 hours later I got another one... The 4319 files.

The first one was about the W32/Dumaru.y@MM and the last one about W32/MyDoom@MM.

Looks like those people at McAfee were working late.
Reply #5 Top
I got 1776 of these last night while I was sleeping. Got to love these dam things.
Reply #7 Top
ya I had two show up today. Luckly Norton caught them right away and I deleated them. They came from the stardock newsgroup... Not saying its stardocks fault or anything.
Reply #9 Top
Earlier today they discovered different variants of the 'mydoom' virus. These versions not only perform DOS attacks on SCO and Microsoft, but they also prevent any connection from an infected computer to any of the AV sites. Most AV proggies are making new DAT updates available now or will later tonight. This is the third DAT update for this virus in as many days, so do not assume you have the latest.